Role Information
Details and metadata
2142ea27-02ad-4094-bfea-2dbac6d24934
Change History
Track all modifications to this role since 2025-12-15 01:08:16+00:00
Updated On
Event Type
Summary & Details
2025-09-25 15:33:01
Initial Scan
Show full JSON
{
"properties": {
"roleName": "Enclave Approver Role",
"type": "BuiltInRole",
"description": "Read all resources in Azure Virtual Enclaves and Approve approval requests within the Enclave",
"assignableScopes": [
"/"
],
"permissions": [
{
"actions": [
"Microsoft.Mission/Operations/read",
"Microsoft.Mission/communities/read",
"Microsoft.Mission/virtualEnclaves/read",
"Microsoft.Mission/virtualEnclaves/endpoints/read",
"Microsoft.Mission/virtualEnclaves/workloads/read",
"Microsoft.Authorization/*/read",
"Microsoft.Insights/alertRules/*",
"Microsoft.Resources/deployments/*",
"Microsoft.Resources/subscriptions/read",
"Microsoft.Resources/subscriptions/resourceGroups/read",
"Microsoft.Resources/subscriptions/resourcegroups/deployments/read",
"Microsoft.Resources/subscriptions/operationresults/read",
"Microsoft.ResourceHealth/availabilityStatuses/read",
"Microsoft.Features/providers/features/read",
"Microsoft.Features/features/read",
"Microsoft.Mission/communities/communityEndpoints/read",
"Microsoft.Mission/communities/transitHubs/read",
"Microsoft.Mission/enclaveConnections/read",
"Microsoft.Mission/virtualEnclaves/enclaveEndpoints/read",
"Microsoft.Mission/approvals/read",
"Microsoft.Mission/approvals/write",
"Microsoft.Mission/enclaveConnections/approvalCallback/action",
"Microsoft.Mission/virtualEnclaves/approvalCallback/action",
"Microsoft.Mission/virtualEnclaves/enclaveEndpoints/approvalCallback/action",
"Microsoft.Mission/communities/communityEndpoints/approvalCallback/action",
"Microsoft.Mission/approvals/initiatorCallback/action",
"Microsoft.Mission/communities/setMaintenanceMode/action",
"Microsoft.Mission/communities/communityendpoints/connect/action",
"Microsoft.Mission/virtualEnclaves/setWorkloadRoleAssignments/action",
"Microsoft.Mission/virtualEnclaves/setEnclaveRoleAssignments/action",
"Microsoft.Mission/virtualEnclaves/setSubnetConfiguration/action",
"Microsoft.Mission/virtualEnclaves/enclaveEndpoints/connect/action",
"Microsoft.Mission/enclaveConnections/setSourceCidr/action",
"Microsoft.Mission/virtualenclaves/setMaintenanceMode/action"
],
"notActions": [],
"dataActions": [],
"notDataActions": []
}
],
"createdOn": "2024-09-03T15:18:13.594Z",
"updatedOn": "2025-09-25T15:33:01.268Z",
"createdBy": null,
"updatedBy": null
},
"id": "/providers/Microsoft.Authorization/roleDefinitions/2142ea27-02ad-4094-bfea-2dbac6d24934",
"type": "Microsoft.Authorization/roleDefinitions",
"name": "2142ea27-02ad-4094-bfea-2dbac6d24934"
}
2025-09-25 15:33:01
Initial Scan
View details
{
"properties": {
"roleName": "Enclave Approver Role",
"type": "BuiltInRole",
"description": "Read all resources in Azure Virtual Enclaves and Approve approval requests within the Enclave",
"assignableScopes": [
"/"
],
"permissions": [
{
"actions": [
"Microsoft.Mission/Operations/read",
"Microsoft.Mission/communities/read",
"Microsoft.Mission/virtualEnclaves/read",
"Microsoft.Mission/virtualEnclaves/endpoints/read",
"Microsoft.Mission/virtualEnclaves/workloads/read",
"Microsoft.Authorization/*/read",
"Microsoft.Insights/alertRules/*",
"Microsoft.Resources/deployments/*",
"Microsoft.Resources/subscriptions/read",
"Microsoft.Resources/subscriptions/resourceGroups/read",
"Microsoft.Resources/subscriptions/resourcegroups/deployments/read",
"Microsoft.Resources/subscriptions/operationresults/read",
"Microsoft.ResourceHealth/availabilityStatuses/read",
"Microsoft.Features/providers/features/read",
"Microsoft.Features/features/read",
"Microsoft.Mission/communities/communityEndpoints/read",
"Microsoft.Mission/communities/transitHubs/read",
"Microsoft.Mission/enclaveConnections/read",
"Microsoft.Mission/virtualEnclaves/enclaveEndpoints/read",
"Microsoft.Mission/approvals/read",
"Microsoft.Mission/approvals/write",
"Microsoft.Mission/enclaveConnections/approvalCallback/action",
"Microsoft.Mission/virtualEnclaves/approvalCallback/action",
"Microsoft.Mission/virtualEnclaves/enclaveEndpoints/approvalCallback/action",
"Microsoft.Mission/communities/communityEndpoints/approvalCallback/action",
"Microsoft.Mission/approvals/initiatorCallback/action",
"Microsoft.Mission/communities/setMaintenanceMode/action",
"Microsoft.Mission/communities/communityendpoints/connect/action",
"Microsoft.Mission/virtualEnclaves/setWorkloadRoleAssignments/action",
"Microsoft.Mission/virtualEnclaves/setEnclaveRoleAssignments/action",
"Microsoft.Mission/virtualEnclaves/setSubnetConfiguration/action",
"Microsoft.Mission/virtualEnclaves/enclaveEndpoints/connect/action",
"Microsoft.Mission/enclaveConnections/setSourceCidr/action",
"Microsoft.Mission/virtualenclaves/setMaintenanceMode/action"
],
"notActions": [],
"dataActions": [],
"notDataActions": []
}
],
"createdOn": "2024-09-03T15:18:13.594Z",
"updatedOn": "2025-09-25T15:33:01.268Z",
"createdBy": null,
"updatedBy": null
},
"id": "/providers/Microsoft.Authorization/roleDefinitions/2142ea27-02ad-4094-bfea-2dbac6d24934",
"type": "Microsoft.Authorization/roleDefinitions",
"name": "2142ea27-02ad-4094-bfea-2dbac6d24934"
}
Latest Role JSON
Raw definition from Azure
{
"properties": {
"roleName": "Enclave Approver Role",
"type": "BuiltInRole",
"description": "Read all resources in Azure Virtual Enclaves and Approve approval requests within the Enclave",
"assignableScopes": [
"/"
],
"permissions": [
{
"actions": [
"Microsoft.Mission/Operations/read",
"Microsoft.Mission/communities/read",
"Microsoft.Mission/virtualEnclaves/read",
"Microsoft.Mission/virtualEnclaves/endpoints/read",
"Microsoft.Mission/virtualEnclaves/workloads/read",
"Microsoft.Authorization/*/read",
"Microsoft.Insights/alertRules/*",
"Microsoft.Resources/deployments/*",
"Microsoft.Resources/subscriptions/read",
"Microsoft.Resources/subscriptions/resourceGroups/read",
"Microsoft.Resources/subscriptions/resourcegroups/deployments/read",
"Microsoft.Resources/subscriptions/operationresults/read",
"Microsoft.ResourceHealth/availabilityStatuses/read",
"Microsoft.Features/providers/features/read",
"Microsoft.Features/features/read",
"Microsoft.Mission/communities/communityEndpoints/read",
"Microsoft.Mission/communities/transitHubs/read",
"Microsoft.Mission/enclaveConnections/read",
"Microsoft.Mission/virtualEnclaves/enclaveEndpoints/read",
"Microsoft.Mission/approvals/read",
"Microsoft.Mission/approvals/write",
"Microsoft.Mission/enclaveConnections/approvalCallback/action",
"Microsoft.Mission/virtualEnclaves/approvalCallback/action",
"Microsoft.Mission/virtualEnclaves/enclaveEndpoints/approvalCallback/action",
"Microsoft.Mission/communities/communityEndpoints/approvalCallback/action",
"Microsoft.Mission/approvals/initiatorCallback/action",
"Microsoft.Mission/communities/setMaintenanceMode/action",
"Microsoft.Mission/communities/communityendpoints/connect/action",
"Microsoft.Mission/virtualEnclaves/setWorkloadRoleAssignments/action",
"Microsoft.Mission/virtualEnclaves/setEnclaveRoleAssignments/action",
"Microsoft.Mission/virtualEnclaves/setSubnetConfiguration/action",
"Microsoft.Mission/virtualEnclaves/enclaveEndpoints/connect/action",
"Microsoft.Mission/enclaveConnections/setSourceCidr/action",
"Microsoft.Mission/virtualenclaves/setMaintenanceMode/action"
],
"notActions": [],
"dataActions": [],
"notDataActions": []
}
],
"createdOn": "2024-09-03T15:18:13.594Z",
"updatedOn": "2025-09-25T15:33:01.268Z",
"createdBy": null,
"updatedBy": null
},
"id": "/providers/Microsoft.Authorization/roleDefinitions/2142ea27-02ad-4094-bfea-2dbac6d24934",
"type": "Microsoft.Authorization/roleDefinitions",
"name": "2142ea27-02ad-4094-bfea-2dbac6d24934"
}
Effective Permissions
Operations granted by this role (74 total)
Permission Patterns (from role definition)
Actions
34 patterns
Microsoft.Mission/Operations/read
Microsoft.Mission/communities/read
Microsoft.Mission/virtualEnclaves/read
Microsoft.Mission/virtualEnclaves/endpoints/read
Microsoft.Mission/virtualEnclaves/workloads/read
Microsoft.Authorization/*/read
Microsoft.Insights/alertRules/*
Microsoft.Resources/deployments/*
Microsoft.Resources/subscriptions/read
Microsoft.Resources/subscriptions/resourceGroups/read
Microsoft.Resources/subscriptions/resourcegroups/deployments/read
Microsoft.Resources/subscriptions/operationresults/read
Microsoft.ResourceHealth/availabilityStatuses/read
Microsoft.Features/providers/features/read
Microsoft.Features/features/read
Microsoft.Mission/communities/communityEndpoints/read
Microsoft.Mission/communities/transitHubs/read
Microsoft.Mission/enclaveConnections/read
Microsoft.Mission/virtualEnclaves/enclaveEndpoints/read
Microsoft.Mission/approvals/read
Microsoft.Mission/approvals/write
Microsoft.Mission/enclaveConnections/approvalCallback/action
Microsoft.Mission/virtualEnclaves/approvalCallback/action
Microsoft.Mission/virtualEnclaves/enclaveEndpoints/approvalCallback/action
Microsoft.Mission/communities/communityEndpoints/approvalCallback/action
Microsoft.Mission/approvals/initiatorCallback/action
Microsoft.Mission/communities/setMaintenanceMode/action
Microsoft.Mission/communities/communityendpoints/connect/action
Microsoft.Mission/virtualEnclaves/setWorkloadRoleAssignments/action
Microsoft.Mission/virtualEnclaves/setEnclaveRoleAssignments/action
Microsoft.Mission/virtualEnclaves/setSubnetConfiguration/action
Microsoft.Mission/virtualEnclaves/enclaveEndpoints/connect/action
Microsoft.Mission/enclaveConnections/setSourceCidr/action
Microsoft.Mission/virtualenclaves/setMaintenanceMode/action